I asked Shopify why my store was blocking customers. They told me it was working correctly.
For weeks support told me nothing was wrong and the platform was performing as expected, while Shopify staff were posting in this very thread acknowledging the VPN problem is real and unresolved. I sent them this post. It made no difference.
They would only accept a HAR file showing the full error. Not the videos, not the screenshots, not any of the evidence I and my customers kept sending showing something was definitely wrong. And it’s a tricky error to catch, because it’s intermittent and by the time you see it, it’s gone.
What happened
On 29 July I finally captured it. I opened my own shop in Chrome. Not a script. Not a crawler. Me, clicking through to my homepage like any customer would.
I got a blank white page with two words on it: local_rate_limited. No branding. No products. No way through. My entire store, gone.
I sent the request ID to support. Shopify pulled the logs at edge and origin. A human being looked at a session where a real person was refused entry to a real shop, and wrote back:
“Shopify’s bot protection assessed this session as automated traffic and applied rate limiting accordingly. This is expected behavior for that type of connection… There is no platform error.”
Why I was flagged as a bot
A VPN was running. Specifically McAfee Total Protection, ordinary consumer antivirus. It switches its VPN on automatically on unsecured Wi-Fi, and McAfee advertises it for shopping and banking. Norton does it. Google One does it. Apple’s Private Relay does it.
That’s not a datacentre. That’s a shopper with antivirus software.
Shopify is openly admitting it blocks VPN traffic, while behaving as though only a handful of unusual people use one.
And if that’s the response, what was the point of asking us for request IDs?
It isn’t just me — and it costs you twice
I’d already sent Shopify video of an actual customer, not me, trying to reach my store from a Facebook link. Three devices. Same blank page every time.
Then they gave me my numbers. 1,688 of these served to my storefront in five days. 91% attributed to “VPNs, hosting providers, datacenters, or Meta infrastructure IPs—not from residential customer connections.” Edge logs only go back five days, so whatever happened before that is gone.
Read that list again. Meta infrastructure. Some Meta traffic genuinely is crawlers and does need limiting. But traffic from Facebook and Instagram also arrives through Meta’s in-app browser, which is how a huge number of paid-social customers reach your store.
And here’s the kicker. You pay Meta to deliver that customer. Meta charges you for the click. Then Shopify refuses to serve them the page. So you have paid for a customer you were never going to be allowed to sell to, and you lose the sale on top. You are being charged twice for the same block, and nothing in your reporting tells you it happened.
I spent £3,531.72 with Meta last month. My Facebook conversion rate has gone from 3.33% in May to 0.78% now.
It isn’t confined to my store
I reproduced the same block on other people’s stores. Shopify wouldn’t accept those because they weren’t my account. I offered to get written permission from the owners and was told they’d have to contact support themselves. One did.
They were told it would be logged as a “frustration.”
So, publicly and on the record:
Shopify is treating VPNs as something a minority of customers use, when it is now standard in most antivirus software. When is Shopify going to stop turning away real customers, and admit the platform is currently broken?